2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-38894 | CRITICAL | 9.8 | 1.7% | Aug 16, 2023 | A Prototype Pollution issue in Cronvel Tree-kit v.0.7.4 and before allows a remote attacker to execute arbitrary code vi... |
| CVE-2023-20017 | CRITICAL | 9.1 | 0.7% | Aug 16, 2023 | Multiple vulnerabilities in Cisco Intersight Private Virtual Appliance could allow an authenticated, remote attacker to ... |
| CVE-2023-20013 | CRITICAL | 9.1 | 0.7% | Aug 16, 2023 | Multiple vulnerabilities in Cisco Intersight Private Virtual Appliance could allow an authenticated, remote attacker to ... |
| CVE-2023-4204 | CRITICAL | 9.8 | 0.3% | Aug 16, 2023 | NPort IAW5000A-I/O Series firmware version v2.2 and prior is affected by a hardcoded credential vulnerabilitywhich poses... |
| CVE-2023-39115 | CRITICAL | 9.8 | 4.6% | Aug 16, 2023 | install/aiz-uploader/upload in Campcodes Online Matrimonial Website System Script 3.3 allows XSS via a crafted SVG docum... |
| CVE-2023-33663 | CRITICAL | 9.8 | 0.5% | Aug 16, 2023 | In the module “Customization fields fee for your store” (aicustomfee) from ai-dev module for PrestaShop, an attacker can... |
| CVE-2023-32493 | CRITICAL | 9.8 | 0.7% | Aug 16, 2023 | Dell PowerScale OneFS, 9.5.0.x, contains a protection mechanism bypass vulnerability. An unprivileged, remote attacker ... |
| CVE-2023-39851 | CRITICAL | 9.8 | 0.7% | Aug 15, 2023 | webchess v1.0 was discovered to contain a SQL injection vulnerability via the $playerID parameter at mainmenu.php. NOTE:... |
| CVE-2023-39850 | CRITICAL | 9.8 | 0.7% | Aug 15, 2023 | Schoolmate v1.3 was discovered to contain multiple SQL injection vulnerabilities via the $courseid and $teacherid parame... |
| CVE-2023-39852 | CRITICAL | 9.8 | 0.8% | Aug 15, 2023 | Doctormms v1.0 was discovered to contain a SQL injection vulnerability via the $userid parameter at myAppoinment.php. NO... |
| CVE-2023-38866 | CRITICAL | 9.8 | 2.1% | Aug 15, 2023 | COMFAST CF-XR11 V2.7.2 has a command injection vulnerability detected at function sub_415588. Attackers can send POST re... |
| CVE-2023-38864 | CRITICAL | 9.8 | 1.1% | Aug 15, 2023 | An issue in COMFAST CF-XR11 v.2.7.2 allows an attacker to execute arbitrary code via the protal_delete_picname parameter... |
| CVE-2023-4344 | CRITICAL | 9.8 | 0.6% | Aug 15, 2023 | Broadcom RAID Controller web interface is vulnerable to insufficient randomness due to improper use of ssl.rnd to setup ... |
| CVE-2023-4342 | CRITICAL | 9.8 | 0.6% | Aug 15, 2023 | Broadcom RAID Controller web interface is vulnerable due to insecure defaults of lacking HTTP strict-transport-security ... |
| CVE-2023-4341 | CRITICAL | 9.8 | 0.6% | Aug 15, 2023 | Broadcom RAID Controller is vulnerable to Privilege escalation to root due to creation of insecure folders by Web GUI |
| CVE-2023-4340 | CRITICAL | 9.8 | 0.6% | Aug 15, 2023 | Broadcom RAID Controller is vulnerable to Privilege escalation by taking advantage of the Session prints in the log file |
| CVE-2023-4338 | CRITICAL | 9.8 | 0.6% | Aug 15, 2023 | Broadcom RAID Controller web interface is vulnerable due to insecure default of HTTP configuration that does not provide... |
| CVE-2023-4337 | CRITICAL | 9.8 | 0.6% | Aug 15, 2023 | Broadcom RAID Controller web interface is vulnerable to improper session handling of managed servers on Gateway installa... |
| CVE-2023-4336 | CRITICAL | 9.8 | 0.6% | Aug 15, 2023 | Broadcom RAID Controller web interface is vulnerable due to insecure default of HTTP configuration that does not safegua... |
| CVE-2023-4329 | CRITICAL | 9.8 | 0.6% | Aug 15, 2023 | Broadcom RAID Controller web interface is vulnerable due to insecure default of HTTP configuration that does not safegua... |
| CVE-2023-4325 | CRITICAL | 9.8 | 0.6% | Aug 15, 2023 | Broadcom RAID Controller web interface is vulnerable due to usage of Libcurl with LSA has known vulnerabilities |
| CVE-2023-4324 | CRITICAL | 9.8 | 0.6% | Aug 15, 2023 | Broadcom RAID Controller web interface is vulnerable due to insecure defaults of lacking HTTP Content-Security-Policy h... |
| CVE-2023-4323 | CRITICAL | 9.8 | 0.6% | Aug 15, 2023 | Broadcom RAID Controller web interface is vulnerable to improper session management of active sessions on Gateway setup |
| CVE-2023-38865 | CRITICAL | 9.8 | 2.1% | Aug 15, 2023 | COMFAST CF-XR11 V2.7.2 has a command injection vulnerability detected at function sub_4143F0. Attackers can send POST re... |
| CVE-2023-38863 | CRITICAL | 9.8 | 1.1% | Aug 15, 2023 | An issue in COMFAST CF-XR11 v.2.7.2 allows an attacker to execute arbitrary code via the ifname and mac parameters in th... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now